Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Artificial intelligence helped attackers repair scripts, change tactics and produce new versions quickly during two intrusion campaigns in Latin America. It did not teach them operational security.
Palo Alto Networks Unit 42 says exposed infrastructure revealed the mechanics of attacks against transportation, government, water and financial organisations in Mexico, Ecuador and Brazil. Researchers found a self-hosted AI interface, openly accessible directories, successive versions of attack scripts and infrastructure names that disclosed their intended functions and targets.
The evidence supports a more useful conclusion than the familiar claim that AI makes every attacker unstoppable. Generative tools can compress the time required to troubleshoot an intrusion. They can help an operator turn an error into the next working command. They do not automatically remove the infrastructure mistakes, naming habits and rushed deployment choices that allow defenders to reconstruct the campaign.
Unit 42 tracks the activity as two separate clusters, CL-CRI-1131 and CL-CRI-1163. The researchers do not claim the same actor ran both. What connects them is the rapid iteration visible in their tooling and the operational clues left behind.
A self-hosted AI console sat beside the intrusion
CL-CRI-1131 targeted organisations in Mexico and Ecuador, including a transportation organisation, federal ministries and municipal water utilities. The attackers relied heavily on tools already present in Windows and used batch scripts to move through multiple stages of discovery, credential access and collection.
Unit 42 observed attempts to access the Security Account Manager database and Active Directory’s NTDS.dit, along with commands involving shadow copies. These are valuable targets because they can expose password material and directory credentials. The campaign also prepared data for exfiltration and maintained infrastructure from an April compromise into June.
A server at 178.128.87[.]160:3000 exposed NextChat, a self-hosted interface used to access commercial large language models. Unit 42 says the combination of that console and the evolving scripts is consistent with AI-assisted troubleshooting. The researchers could see commands being revised after failures and new variants appearing as the operator worked through problems.
That is strong evidence of AI use in the workflow, but it should not be inflated beyond what the research shows. An exposed interface does not prove that every command was generated by a model. The important point is that AI was available as an iterative assistant during a live intrusion, not that the operation was autonomous.
Brazil saw nine versions in two hours
The second cluster, CL-CRI-1163, targeted the Brazilian financial sector. It began with resume-themed phishing and deployed remote-access tools alongside a Go-based SOCKS5 proxy called SockTz.
Unit 42 found nine versions of the proxy attempted within roughly two hours. The associated open directory contained hundreds of scripts with names such as exploit_creative.py, exploit_careful.py and rce_focused.py. The pattern suggests an operator rapidly generating or refining alternatives rather than carefully developing one tool before deployment.
AI changes the economics of that process. A less experienced operator can paste an error into a model, request a correction and try again within minutes. The result does not have to be elegant. It only has to work once on the target in front of them.
The open directory also changed the defender’s view. Instead of seeing a single payload, researchers could inspect the failed attempts, naming conventions and development sequence. The same speed that produced more attacker artifacts also produced more evidence.
Convenience became an intelligence source
Unit 42 found dynamic DNS subdomains, multi-domain certificates and other naming choices that exposed how infrastructure was grouped. Some names described roles or targets directly. Shared SOCKS5 relay infrastructure also helped connect activity inside each cluster.
These are ordinary operational-security failures. AI did not cause them, and AI did not prevent them. Attackers still had to rent servers, configure certificates, move files, name projects and expose services. Each decision created telemetry that defenders could collect independently of the malware running on a victim.
This is the part of AI-enabled intrusion analysis that matters most operationally. Security teams should not focus only on detecting an AI-generated script by its style. That signal is fragile. Infrastructure reuse, exposed services, certificate relationships, unusual proxy traffic and credential-access behaviour remain observable whether a human or a model wrote the command.
The attack still depended on familiar behaviours
The campaigns used techniques defenders already know how to monitor: phishing, living off the land, account-database access, shadow-copy manipulation, remote administration, proxy tunnelling, staging and exfiltration. AI accelerated the attacker’s learning loop, but it did not erase the underlying behaviours.
That distinction should shape defensive priorities. Buying a detector that promises to identify AI-generated malware is less valuable than collecting the telemetry needed to see what the malware actually does. Process creation, script execution, authentication events, access to sensitive directory files, outbound connections and archive creation remain high-value signals.
Identity controls are equally important. Attempts to obtain SAM or directory database material should trigger immediate investigation. Credentials exposed at that stage may outlive the endpoint that first raised the alert, allowing attackers to return through legitimate accounts after the original malware has been removed.
What defenders can take from the research
- Monitor access to SAM, SYSTEM and
NTDS.dit, including attempts that use volume shadow copies. - Alert on rapid sequences of failed and modified scripts, especially when they touch credentials, archives or network configuration.
- Inspect outbound connections from administrative hosts for self-hosted AI interfaces, uncommon proxy services and newly registered dynamic DNS names.
- Hunt for SOCKS5 tunnelling and unexpected Go-based binaries on systems that do not normally run proxy software.
- Use certificate and passive-DNS relationships to map infrastructure even when individual IP addresses change.
- Preserve failed scripts and intermediate payloads. They may reveal more about intent and development than the final successful sample.
- Rotate credentials exposed to a compromised host, rather than treating endpoint cleanup as the end of the incident.
AI raised the tempo, not the quality of secrecy
The risk is real. AI can help attackers who would otherwise stall when a command fails or a payload will not compile. Nine proxy versions in two hours demonstrate how quickly an operator can move through alternatives.
But speed is not invisibility. These campaigns left open directories, exposed tooling and infrastructure relationships that allowed researchers to reconstruct the workflow. Defenders should prepare for faster iteration while resisting the idea that AI makes established detection and incident-response practices obsolete.
The attacker may now have an assistant that never sleeps. The network, identity system and operating system still record what the attacker does.
Sources and further reading
- Palo Alto Networks Unit 42 research on AI tool use targeting Latin American organisations, published 3 September 2026. Unit 42 provided no publication time.
Continue the series: LATAM Cyber & Digital Law Series index


